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(54) Data scrambling and descrambling system 

(57) A system for providing scrambled content, 
comprising a control word generator, each control word 
including a control word identifier, a scrambler for pro- 
viding a stream of scrambled data packets, and an en- 
cryption device for providing entitlement control mes- 
sages (ECM's). One or more consecutive packets are 
scrambled using the same control word (CW). Each 
packet includes a control word identifier identifying the 
control word used. The ECM encryption device provides 
ECM's including a previous control word (CW P ), a cur- 
rent control word (CW C ) and a next control word (CW N ). 
A system for descrambling scrambled content compris- 
es a descrambler for descrambling the scrambled con- 
tent and a decryption device for decrypting ECM's to ob- 
tain control words. The ECM decryption device delivers 



control words to the descrambler and the descrambler 
descrambles the data packets of the scrambled content 
using a control word having a control word identifiercor- 
responding with the control word identifier of the data 
packet to be descrambled. The system further compris- 
es a storage device for storing scrambled content and 
means to control play back of the stored content, going 
fast forward and going backwards. The system is pro- 
grammed to extract ECM's and to provide the ECM's to 
the ECM decryption device for decryption. The system 
is programmed to request the ECM decryption device 
to provide at least a next control word (CW N ) at play 
back or going fast forward, and to provide at least a pre- 
vious control word (CW P ) and a current control word 
(CW C ) at going backwards. 
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Description 

[0001] The invention relates to conditional access 
systems suitable for receiving apparatus provided with 
storage devices with large capacity. The invention spe- s 
cifically relates to a system for providing scrambled con- 
tent according to the preamble of claim 1 and to a sys- 
tem for descrambling scrambled content according to 
the preamble of claim 3. 

[0002] Recently television receiving apparatus have ?0 
been equipped with storage devices with large capacity 
allowing the users to store hours of video content. In this 
manner the user can create a "personal television 11 re- 
cording his favourite programs and the like. Such receiv- 
ing apparatus can be made as a television apparatus, is 
a set-top box or the like. 

[0003] The content stored in the storage devices, 
such as large hard discs, can include scrambled content 
with conditional access, wherein control words are 
needed to descramble the content. Such storage devic- so 
es allow going backwards through the scrambled con- 
tent, wherein however the presently available mecha- 
nisms for cycling control words become difficult to use. 
Going backwards is necessary as the users would like 
to use a VCR-like rewind functionality. However the cur- 25 
rent techniques used for control word cycling are de- 
signed for signals that go forward only. 
[0004] The invention aims to provide a system for pro- 
viding scrambled content and a system for descram- 
bling scrambled content of the above-mentioned type, 30 
wherein a VCR-like rewind function is supported. 
[0005] According to the invention a system for provid- 
ing scrambled content, comprises a control word gen- 
erator, each control word including a control word iden- 
tifier, a scrambler for providing a stream of scrambled 35 
data packets, wherein one or more consecutive packets 
are scrambled using the same control word (CW) and 
wherein each packet includes a control word identifier 
identifying the control word used, and an encryption de- 
vice for providing entitlement control messages *o 
(ECM's), each ECM including at least a next control 
word (CW N ), characterized in that the ECM encryption 
device provides ECM's including a previous control 
word (CW P ), a current control word (CW C ) and a next 
control word (CW N ). 4 * 
[0006] In a second aspect of the invention a system 
for descrambling scrambled content is provided, com- 
prising a descrambler for descrambling the scrambled 
content, a decryption device for decrypting ECM's to ob- 
tain control words, wherein the ECM decryption device so 
delivers control words to the descrambler, wherein the 
descrambler descrambles the data packets of the 
scrambled content using a control word having a control 
word identifier corresponding with the control word iden- 
tifier of the data packet to be descrambled, the system ss 
further comprising a storage device for storing scram- 
bled content and a processing unit with means to control 
playback of the stored content, going fast forward and 



going backwards, wherein the processing unit is pro- 
grammed to extract ECM's and to provide the ECM's to 
the ECM decryption device for decryption, character- 
ized in that the processing unit is programmed to re- 
quest the ECM decryption device to provide at least a 
next control word (CW N ) at play back or going fast for- 
ward, and to provide at least a previous control word 
(CW P ) and a current control word (CW C ) at going back- 
wards. 

[0007] By providing entitlement control messages 
with three control words, i.e. the current, next and pre- 
vious control words, the receiving apparatus can play- 
back stored content from disc in a normal manner, 
wherein further fast forward and rewind functions are 
available. When the receiving apparatus is going back- 
wards through the content, the processing unit picks up 
the first ECM it finds, sends the ECM to the ECM de- 
cryption device and requests the decryption device to 
deliver current and previous keys and loads these keys 
into the descrambler. Processing the ECM's and syn- 
chronizing the provision of control words is relatively 
simple in this manner. 

[0008] The invention will be further explained by ref- 
erence to the drawings in which an embodiment of the 
systems of the invention is shown. 
[0009] Fig. 1 shows a simplified diagram of embodi- 
ments of the system for providing scrambled content 
and the system for descrambling scrambled content ac- 
cording to the invention. 

[001 0] Fig. 2 shows a diagram to explain the operation 
of the systems of the invention. 
[0011] Fig. 1 shows a system 1 for providing scram- 
bled content comprising a control word generator 2 and 
a scrambler 3. The scrambler 3 receives clear content 
and delivers content scrambled using the control words 
provided by the control word generator 2 as encryption 
keys. The control word generator provides a new control 
word every ten seconds for example. As is well-known 
in the art, the control words are generally used as a seed 
for a pseudo-random binary sequence generator, 
wherein the output of the PRBS generator is used for 
scrambling the clear content. Of course other scramble 
systems such as a block cypher system may also be 
used. As such scrambling systems are known per se, 
this is not discussed in detail in this specification as it is 
not part of the present invention. Each control word CW 
has an associated control word identifier, which in case 
of the generally used MPEG system is only one bit, i.e. 
either a zero or a one. In a corresponding manner the 
same control word identifier, i.e. a zero or a one, is as- 
sociated with each scrambled data packet or plurality of 
scrambled data packets scrambled under the control of 
the control word having the same associated identifier 
zero or one. 

[0012] The control words CW 0 and CW 1 are also de- 
livered to an ECM encryption device 4 which encrypts 
the control words using an input key P. The encryption 
device 4 can be made as a smart card. The encrypted 
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ECM's with the control words are inserted into the including the control word required for descrambling the 
scrambled content and broadcasted or delivered in any previous data packet. In this manner a rewind function 
other manner to a number of subscribers each having is supported in an easy manner so that the user can 
a system 5 for descrambling scrambled content. scroll back through the content retrieved from the stor- 
[0013] It is noted that the key P used by the encryption * age device 10 using the control means 9. Of course, 
device 4 can be transferred to the systems 5 in so-called such control means may include a remote control de- 
entitlement management messages which are not vice. 

shown in fig. 1 . Conditional access systems operating [0017] An illustration of the operation of the systems 
with such a hierarchy of keys are known per se and are of the invention is schematically shown in fig. 2. A con- 
not further described in this specification. 10 tent stream with data packets A t B, C and D is shown, 
[0014] The descrambling system 5 comprises a de- wherein it is assumed that data packet A has the control 
scrambler 6 for descrambling the scrambled content word identifier 0, the data packet B the identifier 1, the 
and a decryption device 7 for decrypting ECM's to obtain data packet C the identifier 0 etc. The ECM stream is 
the control words CW. This device 7 can be made as a shown above the data packet stream. As indicated, a 
smart card. Further, the system 5 comprises a process- 1$ new ECM is extracted from the stream shortly before a 
ing unit 8 controlling the operation of the system and transition from data packet A to B, from B to C etc. The 
having a schematically indicated control means 9 allow- ECM extracted from the data stream shortly before the 
ing control of the system by the user. The scrambled beginning of data packet A, includes the previous con- 
content is received by the processing unit 8 and can be trol word CW P1 , the current control word CW A0 , and the 
stored on a storage device 1 0, for example a hard disc 20 next control word CW B1 . The next ECM includes the pre- 
with large capacity. The processing unit 8 forwards the vio us control word CW A0 , the current control word CW B1 
scrambled content to the descrambier 6 and extracts the and the next control word CWqq. During normal play- 
ECM's from the stream and forwards the ECM's to the back, the processing unit 8 will extract the ECM's sub- 
decryption device 7. The decryption device 7, generally sequently from the data stream and will send the ECM's 
made as a secure device such as a smart card, decrypts 25 to the decryption device 7. The processing unit 8 will 
the ECM's received and as controlled by the processing request the decryption device 7 to send the current con- 
unit 8 delivers the control words CW 0 , CW 1 to the de- trol word CW A0 and the next control word CW B1 to the 
scrambler 6. If a data packet with the control word iden- descrambier 6. The descrambier 6 receiving the data 
tifier 0 is received the control word CW 0 is used, if a data packet A with identifier 0, will use the control word CW A0 
packet having the control word identifier 1 is received, 30 to descramble this data packet. At the transition from 
the control word CW 1 is used. data packet A to data packet B, the new identifier 1 in- 
[0015] In the known conditional access system either dicates the descrambier 6 to use the control word CW B1 . 
the current control word CW C and the next control word The same operation applies to the fast forward mode 
CW N is included in the ECM's or only the next control wherein the processing unit 8 will request the decryption 
word CW N . The decryption device 7 decrypts the control 35 device 7 to send the current and next control words to 
words and loads the control words into the descrambier the descrambier 6. 

6. As stated above, the data packets passing the de- [0018] If the user operates the control means 9 for go- 
scrambler 6 have corresponding control word identifiers ing backwards, i.e. a VCR-like rewind function, the 
indicating which control word C W., orCW 0 touse. In nor- processing unit 8 instructs the decryption device 7 to 
mal use, when only going forward, an ECM is extracted *o provide the current control word CW^ and previous 
from the stream and will at least contain the control word control word CW P1 . In this manner the descrambier 6 
CW! or CW 0 to be used at the next transition from iden- can descramble the previous data packet, 
tifier 1 to 0 in the data packet stream. However when [0019] In the above example it is indicated that the 
going backwards through the data stream, the ECM at ECM's are stored as part of the content. It is also pos- 
any location will not have the control word CW P for the « sible to store the ECM's separately with timing informa- 
previous data packet. This means that the processing tion. In this case timing information in the content stream 
unit 8 must look further back then the current data pack- is used by the processing unit 8 to extract or retrieve the 
et being processed by the descrambier in order to find correct ECM's from the storage device 10. 
a previous ECM. This would require an intensive oper- [0020] From the above it will be understood that the 
ation and would mean a high load on the processing ca- so invention provides systems, wherein going backwards 
pacity of the system 5. through the stored video content is allowed without any 
[0016] According to the invention, this problem of lo- significant increase in the load on the processing unit in 
eating an ECM in the data stream is avoided by including processing ECM's and synchronizing control words. It 
in the ECM's three keys, i.e. the previous control word will be clear that the invention can be used with any type 
CW P , the current control word CW C and the next control ss of video or audio content. 

word CW N . In this manner each ECM extracted from the [0021] The invention is not restricted to the above de- 
stream by the processing unit 8 at play back of the con- scribed embodiments which can be varied in a number 
tent stored on the disc 10 contains three control words, of ways within the scope of the attached claims. 
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Claims 

1. System for providing scrambled content, compris- 
ing a control word generator, each control word in- 
cluding a control word identifier, a scrambler for pro- 5 
viding a stream of scrambled data packets, wherein 
one or more consecutive packets are scrambled us- 
ing the same control word (CW) and wherein each 
packet includes a control word identifier identifying 

the control word used, and an encryption device for 10 
providing entitlement control messages (ECM's), 
each ECM including at least a next control word 
(CW N ), characterized in that the ECM encryption 
device provides ECM's including a previous control 
word (CWp), a current control word (CW C ) and a 
next control word (CW N ). 

2. System according to claim 1 , wherein the ECM en- 
cryption device is accommodated in a smart card. 

20 

3. System for descrambling scrambled content, com- 
prising a descrambler for descrambling the scram- 
bled content, a decryption device for decrypting 
ECM's to obtain control words, wherein the ECM 
decryption device delivers control words to the de- 25 
scrambler, wherein the descrambler descrambles 

the data packets of the scrambled content using a 
control word having a control word identifier corre- 
sponding with the control word identifier of the data 
packet to be descrarnbled, the system further com- so 
prising a storage device for storing scrambled con- 
tent and a processing unit with means to control 
play back of the stored content, going fast forward 
and going backwards, wherein the processing unit 
is programmed to extract ECM's and to provide the 35 
ECM's to the ECM decryption device for decryption, 
characterized in that the processing unit is pro- 
grammed to request the ECM decryption device to 
provide at least a next control word (CW N ) at play 
back or going fast forward, and to provide at least *o 
a previous control word (CW P ) and a current control 
word (CW C ) at going backwards. 

4. System according to claim 3, wherein the process- 
ing unit is programmed to request the ECM decryp- 45 
tion device to provide the current control word 
(CW C ) together with a next control word (CW N ) at 
playback or going fast forward and to provide the 
current control word (CW C ) together with a previous 
control word (CW P ) at going backwards. 50 

5. System according to claim 3 or 4, wherein the ECM 
decryption device is accommodated in a smart 
card. 

55 
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